@see http://cgit.drupalcode.org/webform/tree/ISSUE_TEMPLATE.html

Problem/Motivation

Anonymous form submissions create a session cookie. As a result, any further navigation on the site by the user will not hit varnish cached versions of pages and resources. Since Varnish is very heavily relied on for caching anonymous web traffic, this may result in performance and scalability issues. Examining the code, it seems that session variables are only used for bridging anonymous user submission data to logged in users once those users log in or create an account (see setAnonymousSubmission).

Proposed resolution

Would it be possible to use a client side data management method which does not rely on session variables?

Comments

bgronek created an issue. See original summary.

jrockowitz’s picture

Priority: Normal » Major

Right now, there is no way to use client-side storage to track and convert anonymous submissions.

Still, 'anonymous submissions' should only be tracked when a user can 'view own webform submissions'.

The most immediate solution is to check for 'view own submission' in WebformSubmissionStorage:: setAnonymousSubmission.

jrockowitz’s picture

The Webform module for D7 checks if the current user can 'access own webform submissions'.

@see http://cgit.drupalcode.org/webform/tree/webform.module?h=7.x-4.x#n3411

jrockowitz’s picture

Status: Active » Needs review
StatusFileSize
new766 bytes

The attached patch checks if the current user can 'access own webform submissions'.

I am willing to bet the attached untested patch breaks a test or two.

We probably need to add a warning to 'Convert anonymous user drafts and submissions to authenticated user.' that says anonymous users must be able to access their own webform submissions.

Status: Needs review » Needs work

The last submitted patch, 4: anonymous_form-2907459-4.patch, failed testing. View results
- codesniffer_fixes.patch Interdiff of automated coding standards fixes only.

  • d6c744f committed on 2907459-anonymous-session
    Issue #2907459 by jrockowitz: Anonymous form submissions create a...
jrockowitz’s picture

Status: Needs work » Needs review
StatusFileSize
new5.81 KB

Status: Needs review » Needs work

The last submitted patch, 7: anonymous_form-2907459-6.patch, failed testing. View results
- codesniffer_fixes.patch Interdiff of automated coding standards fixes only.

  • 4ef179d committed on 2907459-anonymous-session
    Issue #2907459 by jrockowitz: Anonymous form submissions create a...
jrockowitz’s picture

Status: Needs work » Needs review
StatusFileSize
new11.99 KB
jrockowitz’s picture

  • jrockowitz authored b2875df on 8.x-5.x
    Issue #2907459 by jrockowitz: Anonymous form submissions create a...
jrockowitz’s picture

Status: Needs review » Fixed

I committed the patch. Please download the latest dev release to review.

jrockowitz’s picture

This issue has caused this regression #2908808: Impossible to limit the number of submission by user. I am most likely going to revert the commit and approach the problem with a different solution.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.